Skip to content

rule(template-contract): detect self-parenting identity, unresolved mint pins and leaked template branches #871

Description

@arena-ai-coding-agent

The class

Four open defects in hyperpolymath/rsr-template-repo are one missing check: a repository
asserting provenance it does not have, with nothing able to notice.

These are not stylistic drift. A contributor following #200's instructions clones the
wrong project; a child that believes it is the template mis-reports its own identity to
every agent that reads it.

Why Hypatia should own the detection

This is exactly Hypatia's remit — a rule-shaped, estate-wide, machine-detectable
invariant with a low false-positive rate. The signals are structural and local; none
needs the template checkout.

Proposed rules. Names are suggestions; the estate's module/type naming should win.

Rule Detects Signal
template_contract/TC001 missing provenance repo has no .machine_readable/PROVENANCE.a2ml but has instantiation markers (e.g. no archetypes/, has MINT-PROVENANCE/PROVENANCE refs)
template_contract/TC002 self-parent template_repo equals the repo's own owner/name
template_contract/TC003 unresolved parent pin template_branch/template_commit/template_tree absent or UNASSIGNED on a published repo
template_contract/TC004 leaked template branch a non-default branch with no merge-base against the default branch
template_contract/TC005 stale template identity a file asserts template purpose/UUID (“canonical … template”, the template's UUID) in a repo that is not the template
template_contract/TC006 dangling shipped path shipped content references a path that does not exist in the child (the MINT-PROVENANCE.a2ml case)

TC004 is the highest-value and cheapest: git merge-base --is-ancestor / empty
merge-base against the default branch. It is a pure-graph test, no heuristics.

TC005/TC006 are the #200/#201/#202 family and are text-level, so they can be
advisory-with-confidence like the existing RE-series.

Reference implementation

rsr-template-repo PR #207 adds scripts/check-template-conformance.sh, which implements
T1–T4 (TC001–TC004) with a positive control and five negative controls in
tests/workflows/template_conformance_test.sh. Two bugs in that checker were caught by its
own negative controls before commit — including one that silently disabled the self-parent
check. Lifting the T-logic into a Hypatia rule module is the natural next step.

Verified against a real child, not fixtures: metadatastician/knot-knot → T1/T2/T4 pass;
T3 fails on template_branch/template_tree, which genuinely do not exist in a repo minted
before that commit, and whose provenance records minted_by = "hand" (hardcoded — see below).

A finding that needs Hypatia's own attention

repo-init hardcoded minted_by = "hand", so every scripted mint falsely claimed to be
hand-minted
. Any rule that reasons about which minting path ran would have been reading a
lie. Fixed in PR #207, but it is a live example of the class Hypatia is meant to catch:
a field that is present, plausible, and wrong.

Acceptance

  • T1–T4 (or the estate's naming) implemented as rule modules with stated confidence.
  • Each rule has a negative control that fails. The estate has twice shipped a gate
    that could never fire (chore(deps): bump docker/build-push-action from 6.18.0 to 6.19.2 #49 invisible-character gate matched nothing; chore(deps): bump docker/login-action from 3.7.0 to 4.0.0 #64 Hypatia gate
    was unconditionally vacuous). A rule without a negative control is not a rule.
  • Estate sweep over the ~352 public repos, report-only, producing counts per rule and a
    reviewed repair plan — not an unattended rewrite.
  • TC004 results cross-checked against provenance, so children with legitimate
    multi-branch contracts are not flagged.

Related

rsr-template-repo #200, #201, #202, #203, and PR #207. Lifecycle ownership per
standards#634 (template composition) and standards#636 (lifecycle orchestration):
Hypatia detects and proposes; it must not silently merge unrelated histories.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions